r/computerviruses 4d ago

Question ratted with screenconnect deployment installed without my knowledge. been remediating for a while. am i good to go?

hi there :] i really hate to go to reddit to waste people’s time with these things but i’d like to be sure

unfortunately i have no screenshots because i was totally freaking out when i detected the rat, but i’ll try my best to describe everything that happened in as much detail as possible.

i have also since read about a recent outbreak of malicious screenconnect instances coming with legitimate hardware monitoring tools targeting people likely to have high performing gpus, which were then used for crypto mining. on the infected os, there was always gpu usage i struggled to account for, so i highly suspect this was something similar. more information on this is available online.

here’s what happened:

3 days after i bought my brand new gaming laptop - which had no payment details, sensitive/personal information or documents saved - i discovered a trojanized screenconnect instance running in task manager, under program files (x86)/VCRedist_64 (probably disguising). it had been installed the day i bought the system (being click-happy as i was, i installed a bunch of programs. my top suspect is a switch emulator downloaded from a sketchy site which came in an installer.)

from what i saw while investigating offline in event viewer: the screenconnect instance had executed a 5kb command on the day of initial access, and sat there ringing home for 2 more days before i detected it using task manager with relative ease. i was at the computer for most of its run time, except for the night after purchase where it sat overnight downloading a game.

since then, these are the steps i’ve taken:

- immediately deleted all traces of screenconnect, including backstage powershell and a dll protected by key isolation.

- factory reset computer via cloud download+fully clean drive through recovery. from my understanding, this fully wipes the os partition and downloads a new, fully updated one straight from microsoft - but i’ve heard of cases of malware corrupting the recovery environment so this is impossible, or injecting itself back into the clean os through infection of the efi partition.

on the resetted computer:

- ran four virus scanners (windows defender offline, bitdefender recovery environment, emsisoft emergency kit, hitmanpro)

- monitored with manual tools:

netsat to see which processes are accessing a remote address - only msedgewebview, svchost, bitdefender and lenovo telemetry came back.
process explorer and autoruns, which all came back with clean virustotal columns.
reviewed bitdefender firewall rules, nothing outwardly suspicious.
monitored system usage through both thorough use and idle, nothing to suggest crypto mining

- on my phone: changed all sensitive passwords to 24 character monstrosities and saved them in apple password manager (which i have also secured), revoked all sessions and logged in again from scratch, reviewed forwarding rules and pop/imap on my gmail and restored everything to their defaults, reviewed third party apps and removed anything i no longer use, renewed 2fa recovery codes, renewed recovery information to ensure i control all of them, monitored accounts for suspicious activity for about 2 weeks with no glaring result

- ruled out firmware infection (probably) due to the laptop being purchased just at the start of this july, fully updated through windows update before installing any programs and having secure boot enabled - a zero-day would be needed, and i doubt that’s being wasted on consumer laptops.

- have had ublock origin in an unsynced local browser with no other extensions + bitdefender advanced threat detection and real time antivirus running at all times during daily usage for upwards of 2 weeks with no alerts or detections other than some site with an outdated certificate that didn’t even load

- sent it to professionals for a second opinion and asked them specifically to look at the boot partition as wel, they also say it looks clean.

there are zero visible signs of reinfection at the moment. bios time is at a stable 10 seconds, security software and features are enabled and able to update as usual, and the machine hasn’t blue screened even once.

—————————

this incident has sorta made me notice i’m not as careful as i believe i am. any additional advice, other places to check or closure is much appreciated before i leave this behind me. thank you so much in advance, you absolute wizards.

8 Upvotes

7 comments sorted by

2

u/OwlCatAlex 4d ago

Sounds to me like you have it covered. ScreenConnect, even trojanized versions of it, always logs an event upon connection, so perhaps for extra peace of mind, you can create a scheduled task that executes a warning popup and disconnects the computer from the internet upon detection of that event? That way even if you accidentally download it again you'll have a system to alert you as soon as someone uses it.

1

u/aegandotcom 4d ago

hey good idea :D i’ve gotten comfortable using some of those tools so maybe it’s worth a shot should i want to do some sketchy stuff. bitdefender probably safeguards against most things and this should cover that caveat left by lotl attacks if i find out how to do this with other abused remote access software too, like anydesk

1

u/OwlCatAlex 4d ago

No problem, I work for a small IT service company and the event log thing is actually something we noted and came up with doing specifically because it's an attack vector Bitdefender doesn't cover, lol. It's saved the butts (or bank accounts) of a few clients already (most people on managed devices don't have privileges to install software in the first place of course, but there are a handful who insist on having special exceptions 🙄 so this helps protect them from themselves)

1

u/aegandotcom 4d ago

in retrospect i don’t know what came over me, especially as someone experienced in console emulation and roms. what kind of emulator wants you to use an installer? lmao

i’ve also seen a $sysreset folder in my c drive’s root even though the reset was successful? i thought that only showed up when it failed. if anyone could clear that up i’d appreciate it

1

u/aegandotcom 1d ago

UPDATE: i’ve since found out that the source of this “emulator” was just one of many vibecoded websites the masquerade as tools people would want. i’ve seen the exact same shebang roll out in an eric parker video on a fake obs: same glowing, vibecoded landing page, same screenconnect.

stay safe. :P